logo

23andMe data breach: Hackers stole raw genotype data, health reports

ID: 76975350-33ee-56fd-b878-368cadfb9d0e

STIX ID: report--76975350-33ee-56fd-b878-368cadfb9d0e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-01-25

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

23andMe confirmed a credential-stuffing breach active from April 29 to September 27 in which attackers used reused/stolen credentials to access customer accounts and download raw genotype data and health-related reports for approximately 6.9 million people (including large subsets such as 1 million Ashkenazi Jewish profiles and 4.1 million UK profiles). Some data was posted to BreachForums and an unofficial subreddit; the company required password resets, made two-factor authentication mandatory for all accounts, and faces multiple lawsuits and updated terms of use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.